πΊπΈ
TPI-Abuse
2026-09-01 05:55:24
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.199.8.152 (152.8.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.8.152 (152.8.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:55:20.350636 2026] [security2:error] [pid 30551:tid 30551] [client 35.199.8.152:38590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.grwriters.warnock.ws"] [uri "/.git/config"] [unique_id "apZoyIybiGDJVe8JdxcXSAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·πΊ
DZBOT
2026-09-01 05:48:21
(1 hour ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
π©πͺ
4server
2026-09-01 05:17:59
(2 hours ago)
[TueSep0107:17:56.0498452026][security2:error][pid3705780:tid3705984][client35.199.8.152:0]ModSecuri ...
show more
[TueSep0107:17:56.0498452026][security2:error][pid3705780:tid3705984][client35.199.8.152:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.gruppobalu.com.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"apZgBA36ws4gzC78-lAc_wAAAQw\"]
show less
Port Scan
Brute-Force
Web App Attack
π¦πΉ
penguin-solutions.at
2026-09-01 05:12:12
(2 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 04:10:53
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.8.152 (152.8.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.8.152 (152.8.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:10:46.789952 2026] [security2:error] [pid 584:tid 584] [client 35.199.8.152:54328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gruponovak.com.spyasociados.com"] [uri "/.git/config"] [unique_id "apZQRpv8G22bawqpi_QtOgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-01 04:06:14
(3 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 03:41:02
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.8.152 (152.8.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.8.152 (152.8.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:40:57.158796 2026] [security2:error] [pid 77434:tid 77456] [client 35.199.8.152:42968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.grupojdg.neotienda.com"] [uri "/.git/config"] [unique_id "apZJSe0wKU5I3u64y8dBiQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-01 03:02:34
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-09-01 02:43:33
(4 hours ago)
Banned by Fail2Ban on server
Web App Attack
πΈπͺ
vaia.cloud
2026-09-01 01:35:01
(5 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
π©πͺ
ger-stg-sifi1
2026-09-01 00:59:28
(6 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π³π±
Site.eu
2026-09-01 00:13:15
(7 hours ago)
Excessive multi-domain requests
Brute-Force
π³π±
homeshowdomain.nl
2026-08-31 22:00:20
(9 hours ago)
Auto-ban: >3000 req/min op 2026-08-31
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-08-31 20:26:22
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.8.152 (152.8.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.8.152 (152.8.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 16:26:18.461571 2026] [security2:error] [pid 21933:tid 21933] [client 35.199.8.152:35098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hischurchatwork.iworklife.org"] [uri "/.git/config"] [unique_id "apXjaq-uXILQ25zqNpiGrQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
backslash
2026-08-31 20:21:00
(11 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot